Cisco Expands Splunk AI Capabilities for Secure, On-Premises Enterprise Adoption

Cisco has announced new Splunk innovations designed to help organisations deploy, secure and monitor AI across their environments, including on-premises and private cloud infrastructure. The announcements include an expanded partnership with NVIDIA to bring self-managed Splunk AI to customers, new tools for monitoring AI agents and token costs, and enhancements to security operations and exposure analytics.
“One of the biggest roadblocks to enterprise AI Today is that it’s too hard to deploy,” said Jeetu Patel, President and Chief Product Officer, Cisco. “Customers want to know: Can I trust it to do the job? Can I afford it? And, most importantly, can I secure it? By running Splunk AI on the infrastructure customers already trust, they can move faster to put AI to work in their business with confidence and control.”
Cisco and NVIDIA are expanding their partnership to support self-managed Splunk AI across on-premises, private cloud and air-gapped environments. The Cisco AI POD for Splunk, built on Cisco AI PODs and the Cisco Secure AI Factory with NVIDIA, combines AI runtime software, Cisco infrastructure, NVIDIA accelerated computing and a Kubernetes-based architecture. The configuration is pre-validated and optimised for Splunk AI workloads and is available now.
Customers with existing infrastructure can also work with partners including Accenture, bitsIO, Wipro and World Wide Technology to deploy the solution. Splunk AI Assistant is available now, while Agent Launchpad is expected later this year. Together, they will support agentic investigations and custom agent development, including use cases for security operations centres (SOCs).
Customers can self-host selected open and proprietary AI models, including Cisco Deep Time Series Model, Google Gemma 4 and OpenAI GPT-OSS 20B. NVIDIA Nemotron open models are expected to follow in the coming months.
“Enterprises need to bring AI where their data lives, especially when security and sovereignty requirements require critical workloads to stay on-premises,” said Justin Boitano, Vice President of Enterprise AI at NVIDIA. “By enabling Splunk AI workloads to run with NVIDIA Nemotron open models on NVIDIA accelerated computing, Cisco and NVIDIA are working together to bring AI agents directly to Splunk and giving organizations a high-performance, full-stack foundation for agentic security operations wherever they run their infrastructure.”
Cisco is expanding Splunk’s observability capabilities to help organisations monitor AI agents and understand their operational costs. Splunk Agent Observability, now available in Splunk Observability Cloud and Cisco Cloud Control, evaluates agent and model behaviour, monitors performance across the AI stack and applies runtime guardrails intended to prevent unsafe or inaccurate actions, including hallucinations and sensitive-data leaks.
Its new Tokenomics capabilities track and attribute token expenditure across AI agents and employees’ use of coding tools such as Claude Code, Codex and Cursor. The solution will also use Cisco’s Deep Time Series Model to forecast consumption and help organisations anticipate costs before billing periods end.
Cisco is also introducing updates to its wider observability portfolio. Observability Studio helps teams make applications measurable and production-ready from the outset, while the Network Intelligence App brings Cisco network topology, device health and events into Splunk.
New Essentials and Premier editions of Observability Cloud are intended to simplify purchasing and expansion, with log analytics supporting the investigation of application and infrastructure issues. Splunk is expanding its Agentic SOC Workforce with specialised AI agents supporting detection engineering, proactive threat hunting, investigation, coordinated response and policy governance.
The agents correlate machine data across network, cloud, application and identity environments to help security teams investigate threats, reduce alert noise and accelerate remediation. Cisco says the approach is designed to provide explainable findings while retaining the governance and oversight required by enterprises.
Enhancements to Exposure Analytics will provide broader asset coverage, historical change tracking and business-specific risk insights. By connecting exposure information with live security activity across Cisco, Splunk and third-party environments, the capabilities are designed to help teams identify active risks across their infrastructure.
New capabilities in Splunk Enterprise Security Essentials will bring agentic security operations to a broader range of security teams. Enterprise Security Premier will offer deeper agentic autonomy and the full capabilities of Splunk Enterprise Security.
Cisco and AWS are also expanding their longstanding relationship through a multi-year agreement focused on joint product development. The work will advance agentic SOC capabilities by combining Splunk’s security data platform and detection capabilities with AWS cloud scale. The companies aim to support analysts across detection, investigation and response as AI-driven attacks increase the pressure on security teams.
The collaboration is intended to enable agentic action while retaining the governance and analyst oversight required by enterprise security operations.



